DetoxRansome
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
DetoxRansome is the alias used by a threat actor known to operate from Romania, as indicated by the actor’s self‑identification and the location of the victim company BitDefender, which is also headquartered in Romania. The actor came to public attention in July 2015 after exploiting a vulnerability in a public cloud application component belonging to BitDefender, an anti‑virus firm. The breach exposed unencrypted usernames and passwords belonging to a small fraction of the company’s SMB customers, including some accounts with .gov domain extensions, while the actor asserted that no enterprise or consumer customers were affected. The incident was described by BitDefender as affecting less than one percent of its SMB user base and was promptly contained through vulnerability patching, additional security controls, and forced password resets for potentially impacted accounts.
The actor’s tactics, techniques, and procedures centered on targeting a cloud‑based service rather than deploying traditional malware; they leveraged a flaw in a public cloud component to gain access to two BitDefender cloud servers and claimed to have obtained all login credentials stored there. The actor explicitly stated that the stolen data was unencrypted and referenced the use of Amazon Elastic Compute Cloud (EC2) as the underlying infrastructure, although no fault was attributed to Amazon Web Services itself. Financially motivated behavior is evidenced by the actor’s extortion attempt, in which they demanded a payment of $15,000 to prevent the release of the compromised customer database; when the ransom was not paid, the actor proceeded to leak a subset of the data online. No public sources link DetoxRansome to any state sponsor, criminal consortium, or larger hacking group, and the actor’s affiliation remains limited to the alias and the Romanian location noted in the reporting.
The BitDefender intrusion represents the most significant and publicly documented operation attributed to DetoxRansome, highlighting how even security‑focused organizations can be vulnerable to cloud‑misconfiguration exploits. Law‑enforcement agencies were engaged to investigate the breach, and the case was cited in broader discussions about the susceptibility of security providers to cyber attacks despite their defensive mandates. While the scale of the data exposure was limited, the incident underscored the risks associated with insufficient encryption of credential stores in cloud environments and demonstrated an actor capable of combining vulnerability exploitation with extortion for monetary gain.
Incidents
Attributed incidents are available to members.
1 incident